use become

This commit is contained in:
Robert Kaussow 2018-07-06 23:18:11 +02:00
parent c6f2c9c54f
commit 1f36ad2c49
3 changed files with 43 additions and 37 deletions

View File

@ -1,5 +1,5 @@
--- ---
- name: restart iptables - name: Restart iptables
shell: sleep 2 && systemctl restart iptables shell: sleep 2 && systemctl restart iptables
async: 1 async: 1
poll: 0 poll: 0

View File

@ -1,30 +1,33 @@
--- ---
- name: Set custom iptables rules - name: Setup iptables
iptables_raw: block:
name: 'iptables_custom_rules_{{ item.name }}' - name: Set custom iptables rules
rules: '{{ item.rules }}' iptables_raw:
state: '{{ item.state }}' name: 'iptables_custom_rules_{{ item.name }}'
weight: '{{ item.weight|default(omit) }}' rules: '{{ item.rules }}'
table: '{{ item.table|default(omit) }}' state: '{{ item.state }}'
with_items: '{{ iptables_custom_rules }}' weight: '{{ item.weight|default(omit) }}'
loop_control: table: '{{ item.table|default(omit) }}'
label: "{{item.name}}" with_items: '{{ iptables_custom_rules }}'
tags: iptables loop_control:
label: "{{item.name}}"
tags: iptables
- name: Set default iptables head rules - name: Set default iptables head rules
iptables_raw: iptables_raw:
name: iptables_default_head name: iptables_default_head
weight: 10 weight: 10
keep_unmanaged: '{{ iptables_keep_unmanaged }}' keep_unmanaged: '{{ iptables_keep_unmanaged }}'
state: present state: present
rules: '{{ iptables_default_head }}' rules: '{{ iptables_default_head }}'
tags: iptables tags: iptables
- name: Set default iptables tail rules - name: Set default iptables tail rules
iptables_raw: iptables_raw:
name: iptables_default_tail name: iptables_default_tail
weight: 99 weight: 99
keep_unmanaged: '{{ iptables_keep_unmanaged }}' keep_unmanaged: '{{ iptables_keep_unmanaged }}'
state: '{{ (iptables_default_tail != "" ) | ternary("present", "absent") }}' state: '{{ (iptables_default_tail != "" ) | ternary("present", "absent") }}'
rules: '{{ iptables_default_tail }}' rules: '{{ iptables_default_tail }}'
tags: iptables tags: iptables
become: True

View File

@ -1,11 +1,14 @@
--- ---
- name: Install package - name: Install iptables
package: block:
name: '{{ iptables_package }}' - name: Install packages
state: latest package:
name: "{{ iptables_package }}"
state: latest
- name: Enable and start service - name: Enable and start service
service: service:
name: iptables name: iptables
enabled: True enabled: True
state: started state: started
become: True